European law enforcement has seized the infrastructure of the KillSec ransomware group following an international investigation into around 1,000 suspected cyberattacks worldwide.
The operation, carried out on September 30 under the name Operation KillSwitch, resulted in three provisional arrests and eight searches across Greece, Romania, Spain and the United Kingdom. Investigators believe a 16-year-old was the group’s suspected main operator.
Authorities also took control of KillSec’s leak site, securing at least 110 terabytes of stolen data and preventing further unauthorised access. The group had used the site to pressure victims into paying ransoms by threatening to publish stolen information.
KillSec has reportedly been active since around 2024, gaining access to organisations by exploiting software vulnerabilities and poorly secured entry points, particularly cloud storage systems. Investigators have identified around 500 attacks that are believed to have been successful, although that number could increase as authorities analyse the seized evidence.
After accessing victims’ systems, the attackers copied sensitive internal files to infrastructure they controlled. Organisations were then listed on KillSec’s dark web leak site and threatened with the public release of their data. In cases where victims refused to pay, the stolen files could be offered for free download. Investigators said some victims paid significant ransom amounts.
Authorities also discovered that the group used artificial intelligence to help build and maintain its ransomware infrastructure and identify potential targets.
The investigation identified several suspected members with different roles, including an administrator, developer, negotiator and affiliate. The suspected administrator and main operator is 16 years old, while the alleged developer turned 18 in August 2026 and was a minor when some of the suspected offences took place. Investigators are continuing to look for other possible members.
During the wider investigation, authorities brought five central servers under their control. These included infrastructure allegedly used to manage KillSec’s operations and store stolen victim data. Police also seized devices and other assets and took control of domains operated by the group, redirecting visitors to a law enforcement seizure notice.
Investigators are now examining the seized devices and data while tracing suspected criminal proceeds, including cryptocurrency transactions. The evidence could help authorities identify additional victims, attacks and people connected to the group.
The operation was led by the Hamburg State Criminal Police Office and Hamburg Public Prosecutor’s Office, with investigators from several European countries and the United States working alongside Europol and Eurojust. Cybersecurity companies Bitdefender and Group-IB also supported the investigation.
Europol’s European Cybercrime Centre helped connect investigators, analyse intelligence, trace cryptocurrency and examine digital evidence. Eurojust coordinated judicial cooperation and helped authorities synchronise the international enforcement action.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The investigation remains ongoing, with authorities continuing to analyse the seized infrastructure and determine the full extent of KillSec’s activities.
KillSec Ransomware Group Targeted in International Crackdown



